Sec Bug->Req #78305 [Dup]: Injection of INI settings into FPM worker processes
| From: | bukka@php.net | Date: | Sat, 04 Dec 2021 18:27:07 +0000 |
| Subject: | Sec Bug->Req #78305 [Dup]: Injection of INI settings into FPM worker processes | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-238174@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78305&edit=1
ID: 78305
Updated by: bukka@php.net
Reported by: mp at webfactory dot de
Summary: Injection of INI settings into FPM worker processes
Status: Duplicate
-Type: Security
+Type: Feature/Change Request
Package: FPM related
Operating System: Ubuntu 18.04.2 LTS
PHP Version: 7.1.30
Block user comment: N
Private report: Y
New Comment:
This behaviour is on purpose and its mitigation (optional disabling) is treated as a feature.
Previous Comments:
------------------------------------------------------------------------
[2019-08-14 05:53:38] stas@php.net
Duplicate of bug #77190
------------------------------------------------------------------------
[2019-07-17 10:08:19] mp at webfactory dot de
Description:
------------
Dear Security team,
I am not familiar with reporting security issues and hope that this is the right way to report it,
to make it helpful to you and that you share my assessment.
The underlying issue has been known for more than 8 years:
https://bugs.php.net/bug.php?id=53611
The problem is that if you're able to access the unix socket and/or network port for a
particular PHP-FPM pool, you can use the "PHP_VALUE" variable to send ini settings
(including PHP_INI_SYSTEM) to the FPM worker process.
This setting *will persist* beyond the single request - that is, it will affect requests and scripts
executed by the particular worker process.
You could, for example, configure an auto_prepend_file and so effectively be able to run code during
the subsequent request served by the FPM worker process.
For shared hosting environments, the recommendation probably is to have different PHP-FPM pools per
vhost. But as long as the unix and/or network socket can be accessed by users or code from other
vhosts, this bug is probably an issue.
I don't know if it is reliably possible to limit unix domain socket or even network port access
for PHP scripts? I mean, if I can run a script in one virtual host, I can probably access all
network ports, even if FPM is bound to 127.0.0.1?
Thanks for your time and patience!
-mp.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78305&edit=1